Skip to content

Bound authenticated manifest buckets and incremental updates - #1239

Merged
DecisionNerd merged 5 commits into
mainfrom
fix/1204-bounded-manifest
Sep 10, 2026
Merged

DecisionNerd merged 5 commits into
mainfrom
fix/1204-bounded-manifest

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Problem and result

The current heterogeneous construction fixture stores 352 authenticated payload entries in 483 manifest objects using 1,978,368 allocated bytes. Bounded eight-entry buckets reduce the actual production manifest to 209 objects / 856,064 bytes (56.7% less), below #1204's 1,536,000-byte budget. The exact public semantic fingerprint is unchanged.

Node format v3 adds explicit encoded and decoded-field admission, bounded parsing, full ancestral-route validation, incremental ninth-entry splitting and bounded deletion collapse. Production manifest readers share the encoded-node limit; independent route-table limits remain. Current roots are immutable and old node versions are refused without a compatibility reader or migration layer.

Evidence

  • Maximum escaped fields, oversized/duplicate/misplaced nodes, absent lookup, corruption and version refusal; exact eight-to-nine split/collapse and retained roots.
  • 128/256/512-entry deterministic update ladder: three replacement reads/installs and three deletion reads at each size, with successful/absent lookup ceilings.
  • Frozen source-bound public construction/reopen/query/export/full-verify/clean-import measurements, separate CPU/RSS, application/OS I/O, deduplicated disk sampling and total-project census: docs/development/evidence/bounded-manifest-1204.json.
  • Full-workload write traffic rises by 58,054 bytes; no query-speed or hard native-memory claim. Historical test(storage): establish permanent topology and identity compaction budgets #1196's different 544-entry inventory is reported separately.

Local checks: cargo fmt --all -- --check, cargo clippy --workspace -- -D warnings, make pre-push-fast, and make gate-registry-check pass. The public fixture suite passes all 45 cases; the workspace run also passed 737 API unit tests, 118 BDD scenarios / 443 steps, and 17 fixed-hop regressions. Storage validation passes 1,091 unit and 74 integration cases; its sole failure is the existing hard-coded /tmp admission test (GF_UNSUPPORTED_FILESYSTEM, filesystem_class_unproven). No skip or assertion change was made for that environment constraint.

The workspace run exposed an outdated scale negative fixture using the old 67-node ceiling. It now exceeds the new 81-node structural ceiling and its rejection test passes; independent review verified the gate remains strict. make pre-push reached Rust coverage and failed only at that same /tmp test (1,090 storage unit tests passed); its final-source facade suite passed 45/45 and scale-accounting suite passed 30/30. Python/Node prerequisites were provisioned from the locked dependencies before that run. Full local validation is not claimed green. Required exact-head CI remains the merge gate.

Closes #1204


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 79323c53-3563-4f6e-aff8-6e5c11711994

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added core Core source code changes documentation Improvements or additions to documentation labels Sep 10, 2026
@DecisionNerd
DecisionNerd merged commit c74a529 into main Sep 10, 2026
23 checks passed
@DecisionNerd
DecisionNerd deleted the fix/1204-bounded-manifest branch September 10, 2026 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core Core source code changes documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): bound manifest allocation with authenticated bucket leaves

1 participant